Every engagement is delivered by a senior practitioner, fixed-price, with audit-ready evidence at every milestone — inside your existing Microsoft 365 environment, on Checkpoint, our own console included in the engagement. No third-party platform, no junior staff, no surprises.
Not sure where to start?
Frameworks we deliver
Every framework is delivered with the same methodology and evidence infrastructure — so when you need more than one, the work overlaps rather than duplicates. Select a framework to see how it runs.
Most organisations come to us with a specific trigger — a customer requirement, a contract condition, an insurer question, or a failed audit. Use this as a guide, or book a free 30-min call and we'll tell you exactly what you need.
→ Essential Eight uplift — assessed, implemented to ML2, evidenced.
→ Essential Eight assessment first, then targeted uplift on the gaps they care about.
→ ISO 42001 — model inventory, risk assessments, human oversight, audit-ready evidence.
→ ISO 27701 — DPIAs, ROPAs, data rights workflows, built on top of ISO 27001.
→ DISP / ISM / IRAP — mapped to your Microsoft E5 environment.
Need more than one? Most mid-market programmes combine 2–3 frameworks — we scope them together so the work overlaps rather than duplicates.
The baseline certification most enterprise, government, and procurement panels require. Gap analysis, risk treatment, SoA, and audit-ready evidence — all automated in Microsoft 365.
Australia's baseline cyber security framework — all eight controls assessed, implemented, and evidenced to ML2. Fixed-price, milestone-gated, Microsoft 365-native.
IS18:2018 delivered as what it actually is — an ISO 27001-aligned ISMS plus Essential Eight, plus QGISCF classification, CSU incident reporting, and the accountable officer's 30 September annual return. Everything stays inside your own tenant.
Right Fit For Risk for Employment Services providers — the full ISM Statement of Applicability (989 controls + 7 program-deed obligations) delivered on an ISO 27001 ISMS with Essential Eight uplift. Nearly a third of the SoA assessed automatically from your Microsoft 365 tenant.
Model inventory, AI risk assessments, human oversight, and monitoring — built inside your existing Microsoft 365 stack. Aligned to the Australian AI Safety Standard and EU AI Act.
Trust Services Criteria mapped to your systems. Type I and Type II readiness with reusable, automated evidence that unlocks US and global enterprise contracts.
Extends ISO 27001 into privacy. DPIAs, ROPAs, data rights workflows, and third-party privacy risk — streamlined inside Microsoft 365 without a third-party platform. Aligned to the Australian Privacy Act.
Defence Industry Security Programme, Information Security Manual, and IRAP readiness. Map your existing Microsoft E5 stack to ASD and ISM requirements and get government panel-ready.
Align to NIST CSF (Identify → Protect → Detect → Respond → Recover) — mapped to ISO 27001 and Essential Eight so work overlaps rather than duplicates.
A free 30-minute call will tell you which framework fits your situation, what the fastest path looks like, and what it's likely to cost. No obligation.
Hi! I’m the Compliance365 AI. I can help you work out which security or privacy framework you need, explain what’s involved, and answer questions about ISO 27001, SOC 2, Essential Eight, and more.
What can I help you with today?
Messages are sent to our AI assistant (Claude, by Anthropic) to generate a reply — not stored as part of your account and not used to train AI models.